MSTW League Manager - Cross Site Scripting (XSS) vulnerability
mediumCross Site Scripting (XSS) vulnerability
- CVSS:
- 6.5
- Affected:
- up to 2.10
- Fix:
- No patched version reported
- Disclosed:
- Apr 2, 2026
plugin
4 known security issues reported for the Mstw League Manager WordPress plugin. Most recent disclosed Apr 2, 2026.
Running Mstw League Manager on your site? Check whether your installed version is affected.
Scan your site freeCross Site Scripting (XSS) vulnerability
The MSTW League Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pag...
The MSTW League Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.10. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action granted they can trick a site ad...
[en] Cross-Site Request Forgery (CSRF) vulnerability in Mark O'Donnell MSTW League Manager allows Stored XSS. This issue affects MSTW League Manager: from n/a through 2.10.
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free